These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-11674 is a high-severity vulnerability in Google Chrome prior to version 149.0.7827.103. This use-after-free issue in the Guest View component allows remote attackers to execute arbitrary code inside a sandbox via a crafted HTML page. The vulnerability has a CVSS score of 8.8 and is considered High severity by Chromium.
CVE-2026-11673 is a high-severity vulnerability in Google Chrome prior to version 149.0.7827.103. This use-after-free issue in InterestGroups allows remote attackers to execute arbitrary code inside a sandbox via a crafted HTML page. The vulnerability has a CVSS score of 8.8 and is considered High severity by Chromium.
CVE-2026-11672 is a High-severity vulnerability in Google Chrome on Android, allowing a remote attacker to potentially perform a sandbox escape via a crafted HTML page. The vulnerability is caused by a heap buffer overflow in the GPU.
CVE-2026-11671 is a critical vulnerability in Google Chrome prior to version 149.0.7827.103. The vulnerability is caused by a use after free in the Navigation component, which could allow a remote attacker to potentially perform a sandbox escape via a crafted HTML page. The CVSS score for this vulnerability is 9.6, indicating a high severity.
CVE-2026-11670 is a high-severity vulnerability in Google Chrome prior to version 149.0.7827.103. This use-after-free issue in the PDF component allows remote attackers to execute arbitrary code inside a sandbox via a crafted PDF file. The vulnerability has a CVSS score of 8.8 and is considered High severity by Chromium. It was published on [cvePublishedAt] and last modified on [cveModifiedAt].
CVE-2026-11669 is an out of bounds read vulnerability in Media in Google Chrome on ChromeOS prior to 149.0.7827.103. A remote attacker who had compromised the renderer process could obtain potentially sensitive information from process memory via a crafted HTML page. The CVSS score for this vulnerability is 5.3, with a severity rating of MEDIUM.
CVE-2026-11668 is a High severity vulnerability in Google Chrome on Linux, ChromeOS prior to 149.0.7827.103. This issue involves an uninitialized use in Codecs that allows a remote attacker to leak cross-origin data via a crafted video file. The vulnerability has a CVSS score of 4.3, indicating a Medium severity level.
CVE-2026-11667 is an out of bounds read vulnerability in WebRTC in Google Chrome prior to 149.0.7827.103. A remote attacker who had compromised the GPU process could potentially exploit heap corruption via a crafted HTML page. The CVSS score for this vulnerability is 7.5, indicating a High severity. This CVE was published on 2026-06-09T00:16:49.853Z and modified on 2026-06-09T14:53:38.863Z.
CVE-2026-11666 is a Medium severity vulnerability in Google Chrome prior to version 149.0.7827.103. The vulnerability is caused by insufficient validation of untrusted input in the Input component, allowing a remote attacker to perform UI spoofing via a crafted HTML page. The Chromium security severity is rated as High.
CVE-2026-11665 is a vulnerability in Google Chrome's Dawn component. An out-of-bounds read issue was discovered in the Dawn component of Google Chrome on Windows. This vulnerability could allow a remote attacker to leak cross-origin data via a crafted HTML page. The issue has been addressed in Google Chrome version 149.0.7827.103 or later.
CVE-2026-11664 is a high-severity vulnerability in Google Chrome prior to version 149.0.7827.103. The vulnerability is caused by a use-after-free issue in the Payments component, which could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page. The CVSS score for this vulnerability is 8.8, indicating a high level of severity.
CVE-2026-11663 is a High severity vulnerability in Google Chrome prior to version 149.0.7827.103. The vulnerability is caused by a use after free in Skia, which could allow a remote attacker who has compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. The CVSS score for this vulnerability is 8.3, indicating a High severity.
CVE-2026-11662 is a High severity vulnerability in Google Chrome prior to 149.0.7827.103. The vulnerability is caused by a type confusion in bindings, which allows a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. The CVSS score for this vulnerability is 8.8, indicating a High severity. The vulnerability was published on [cvePublishedAt] and modified on [cveModifiedAt].
CVE-2026-11661 is a high-severity vulnerability in Google Chrome on Windows, allowing a remote attacker to potentially perform a sandbox escape via a crafted HTML page. The vulnerability is caused by a use-after-free issue in the Views component. Successful exploitation could allow an attacker to execute arbitrary code in the context of the sandbox.
CVE-2026-11660 is a High-severity vulnerability in Google Chrome prior to version 149.0.7827.103. The issue involves insufficient validation of untrusted input in the New Tab Page, allowing a remote attacker who has compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. The vulnerability has a CVSS score of 8.3 and is classified as High severity.
CVE-2026-11659 is a critical vulnerability in Google Chrome on Linux, with a CVSS score of 9.6. The vulnerability is caused by an integer overflow in the UI, which allows a remote attacker to potentially perform a sandbox escape via a crafted HTML page. The vulnerability was published on June 9, 2026, and has been assigned a high severity rating by Chromium.
CVE-2026-11658 is a High-severity vulnerability in Google Chrome prior to version 149.0.7827.103. The issue involves insufficient validation of untrusted input in Extensions, allowing a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.
A high-severity vulnerability, CVE-2026-11657, was discovered in Google Chrome on Mac. This use after free vulnerability in Payments allowed a remote attacker to execute arbitrary code via a crafted HTML page.
CVE-2026-11656 is a use after free vulnerability in ServiceWorker in Google Chrome prior to 149.0.7827.103. An attacker who convinced a user to install a malicious extension could potentially perform a sandbox escape via a crafted Chrome Extension. The vulnerability has a CVSS score of 8.3 and is considered High severity by Chromium. The CVE was published on [cvePublishedAt] and last modified on [cveModifiedAt].
CVE-2026-11655 is an integer overflow vulnerability in the Media component of Google Chrome on Mac systems. This issue was present prior to version 149.0.7827.103 and could allow a remote attacker, who had already compromised the renderer process, to potentially perform a sandbox escape via a specially crafted HTML page. The vulnerability has been classified as High severity by the Chromium security team.
CVE-2026-11654 is a use-after-free vulnerability in the CameraCapture component of Google Chrome on Mac systems. This vulnerability, with a CVSS score of 9.6, could allow a remote attacker to potentially escape the sandbox by providing a specially crafted HTML page. The vulnerability was published on June 9, 2026, and has been categorized as High severity by the Chromium security team.
CVE-2026-11653 is a High-severity vulnerability in Google Chrome's Extensions. A remote attacker who had compromised the renderer process could bypass site isolation via a crafted HTML page. The vulnerability was patched in Chrome version 149.0.7827.103.
CVE-2026-11652 is a High severity vulnerability in Google Chrome prior to 149.0.7827.103. The vulnerability is a use after free in Extensions, which could allow a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. The CVSS score for this vulnerability is 8.3, indicating a High severity. The vulnerability was published on [cvePublishedA [truncated]
CVE-2026-11651 is a critical vulnerability in Google Chrome prior to version 149.0.7827.103. The vulnerability is caused by a use-after-free issue in the Network component, which can be exploited by a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. The vulnerability has a CVSS score of 9.6 and is considered critical.
CVE-2026-11650 is a Use after free vulnerability in V8 in Google Chrome prior to 149.0.7827.103. This vulnerability allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. The CVSS score for this vulnerability is 8.8, indicating a High severity. The vulnerability was published on [cvePublishedAt] and modified on [cveModifiedAt].
CVE-2026-11649 is a Use after free vulnerability in V8 in Google Chrome prior to 149.0.7827.103. This vulnerability, with a CVSS score of 8.8, could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. The vulnerability was published on June 9, 2026, and modified later that day.
CVE-2026-11648 is a high-severity vulnerability in Google Chrome on Windows, allowing remote attackers to potentially exploit heap corruption via a crafted HTML page. The vulnerability is caused by a use-after-free issue in the FullScreen component. Users are advised to update to Chrome version 149.0.7827.103 or later to mitigate this vulnerability.
CVE-2026-11647 is a high-severity vulnerability in Google Chrome on Android prior to version 149.0.7827.103. The vulnerability is a use-after-free issue in the Printing component, which could allow a remote attacker who has compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. The CVSS score for this vulnerability is 8.3, indicating a high level of severity.
CVE-2026-11643 is a high-severity vulnerability in Google Chrome prior to version 149.0.7827.103. The vulnerability is caused by a use after free in the Proxy component, which could allow a remote attacker to execute arbitrary code via malicious network traffic. The Chromium security severity of this vulnerability is Critical, with a CVSS score of 8.1.
CVE-2026-11642 is a high-severity vulnerability in Google Chrome prior to version 149.0.7827.103. The vulnerability is a use-after-free issue in Web Apps, which could allow a remote attacker who has compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. The CVSS score for this vulnerability is 8.3, indicating a high level of severity.